WSL in the Malware Ecosystem, (Wed, Feb 11th)
ID: 7f804689-2cd6-59c1-9a97-f19756662de7
STIX ID: report--7f804689-2cd6-59c1-9a97-f19756662de7
Feed Name: SANS ISC Diary
Threat Score
This report analyzes a Cryxos infostealer sample (ottercookie-socketScript-module-3.js, SHA256:f44c2169250f86c8b42ec74616eacb08310ccc81ca9612eb68d23dc8715d7370) that detects Windows Subsystem for Linux (WSL), retrieves the Windows username via cmd.exe and /mnt/c/Users, and adds the /mnt mount to its search priority to access host drives—demonstrating how WSL can be abused as a LOLBIN to exfiltrate data; the report includes code snippets and indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
